Security best practices

Article3 min read

What you should do

  • Keep secret keys on your server, in environment variables or a secrets manager. Never in browser or mobile code, URLs, logs, or Git.
  • Use one key per server or service, named clearly, so you can revoke one without touching the others.
  • Limit live keys to your servers’ IP addresses where you can.
  • Roll keys when someone with access leaves, and at least once a year.
  • Verify every webhook signature and reject events older than 5 minutes.
  • Only request signing links for people your app has already identified.
Caution
Think a key leaked? Roll it right away. The old key keeps working for 24 hours, or revoke it to stop it immediately.

What Notriv does

  • Stores only a one-way fingerprint of each key. Nobody, including Notriv staff, can read a key back.
  • Asks you to re-enter your password (or an emailed code) before creating or rolling a live key, and emails the account owner every time.
  • Refuses keys sent in URLs and slows down addresses that try wrong keys.
  • Accepts HTTPS only.
  • Keeps test and live data fully separate.
  • Signs every webhook with a timestamp, and only delivers to public https:// addresses.
  • Records every action on an envelope in its audit trail.

Report a problem

Found a security issue? Email security@notriv.com. Please include the request_id of any request involved.

Was this page helpful?